Live data from Hacker News

Delve – Fake Compliance as a Service

deepdelver.substack.com

41–50 of 327 posts

Re: Delve – Fake Compliance as a Service

#41
Delve did not even try to fake the reports well. They could have used AI tooling to write somewhat plausible Assertions of Management, but they just dropped in clear form submissions to the reports they provided. Here is an example from Cluely:

> We have prepared the accompanying description of Cluely, Inc., system titled "Cluely is a desktop AI assistant to give you answers in real-time, when you need it." throughout the period June 27, 2025 - September 27, 2025(description), based on the criteria set forth in the Description Criteria DC Section 200 2018 Description Criteria for a Description of a Service Organization’s System in a SOC 2 Report (description criteria).

> The description is intended to provide users with information about the "Cluely is a desktop AI assistant to give you answers in real-time, when you need it." that may be useful when assessing the risks arising from interactions with Cluely, Inc. system, particularly information about the suitability of design and operating effectiveness of Cluely, Inc. controls to meet the criteria related to Security, Availability, Processing Integrity, Confidentiality and Privacy set forth in TSP Section 100, 2017 Trust Services Principles and Criteria for Security, Availability, Processing Integrity, Confidentiality and Privacy (applicable trust services criteria).

I mean, just re-read this sentence:

> The description is intended to provide users with information about the "Cluely is a desktop AI assistant to give you answers in real-time, when you need it." that may be useful

It makes no sense at all.

Someone implemented the code to automate this report mill, and didn't think to even smooth it out with an LLM! There was clear intent here.

To imagine that an auditor reviewed and stamped this as a coherent body of work beggars belief.

Re: Delve – Fake Compliance as a Service

#43
post #37

This seems like a hit job by a competitor. Really ruthless. > Two months ago, an email went out to a few hundred Delve clients informing them that Delve had leaked their audit reports, alongside other confidential information, through a Google spreadsheet that was publicly accessible. Who leaked the audit reports? Who sent this email? Who is taking the time to write this analysis and kill the company? In my opinion,…

There's no need for some conspiracy.

It's a juicy story to talk about that hits a lot of checkboxes that make it viral --

  1. the hustle culture they promoted online was gross
  2. they followed the 30u30 Forbes pattern like Liz Holmes, FTX, etc. 
  3. they're a YC co, so their's plenty of popular voices supporting them
The 3rd isn't to slight the program but folks definitely slam any companies that seem to be in the moral gray area as a proof the program is nihilistic and a net negative. People like to shove mistakes in the face of "successful" folks like investors/VCs.

Finally, the security and compliance community is litigious by their nature and this startup, in general, was a net negative for a lot of people who do fractional / consulting work in security.

Re: Delve – Fake Compliance as a Service

#44
post #3

Forbes 30u30 pipeline remains undefeated. How did none of this come up during diligence? Feels like a prime example of too good to be true.

> How did none of this come up during diligence?

The article states that, "Even though we knew we’d technically be lying about our security to anyone we sent these policies to for review ... we decided to adopt these policies because we simply didn’t have the bandwidth to rewrite them all manually."

Re: Delve – Fake Compliance as a Service

#45
post #37

This seems like a hit job by a competitor. Really ruthless. > Two months ago, an email went out to a few hundred Delve clients informing them that Delve had leaked their audit reports, alongside other confidential information, through a Google spreadsheet that was publicly accessible. Who leaked the audit reports? Who sent this email? Who is taking the time to write this analysis and kill the company? In my opinion,…

There's no need for some conspiracy. It's a juicy story to talk about that hits a lot of checkboxes that make it viral -- 1. the hustle culture they promoted online was gross 2. they followed the 30u30 Forbes pattern like Liz Holmes, FTX, etc. 3. they're a YC co, so their's plenty of popular voices supporting them The 3rd isn't to slight the program but folks definitely slam any companies that seem to be in the moral…

What's more surprising to me, as a layperson, is that I found this out and investigated their shady auditor network in late December. It didn't take much work.

Insight Partners invested in a 32 MILLION DOLLAR ROUND without any apparent shred of due diligence. What does that say about the VC market writ large?

Re: Delve – Fake Compliance as a Service

#46
Cluely and HockeyStack are scam companies too.

Cluely did the ChatGPT wrapper to cheat on interviews then sold the customer data to recruiters. The whole company promise is a scam, and useless since we have LLMs.

HockeyStack held contests for people to win cars etc and never delivered. They also lied about having revenues and a product when they had nothing built. Along with Greptile they were doing 7day weeks of unpaid labor from “trial periods”.

Scams all around.

Re: Delve – Fake Compliance as a Service

#47
post #39

Earlier quoted context omitted.

Respectfully, I think there may be an issue with your voting ring detection, which is that if multiple people try to submit the same article and are redirected to an existing post and they upvote it, that might be setting off the voting ring alert. Can you check that? I would imagine that's what happened here.

That's definitely not what happened here. The data would be quite different in that case. Edit: 10% of the votes came from resubmissions of the URL. The other 90% came from other sources.

Curious to know! I submitted the duplicate article and most definitely did not work with any voting ring.

Re: Delve – Fake Compliance as a Service

#49
post #21

Earlier quoted context omitted.

It is being suppressed by @dang, I believe they may have a policy that allows suppression for bad YC-related news.

Moderators didn't see it, and our policy is the precise opposite of this – see https://hn.algolia.com/?dateRange=all&page=0&prefix=false&qu... or, for more color, https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que... . We've restored it to the front page now.

Yes, but your team claimed this set off "voting ring" behavior [0] and it was suppressed for nearly a day because of that. I am very curious how you determine what is, or is not, "voting ring" behavior. I believe Dang is responding in another thread about that.

[0]: https://news.ycombinator.com/item?id=47457689

Re: Delve – Fake Compliance as a Service

#50

Cluely and HockeyStack are scam companies too. Cluely did the ChatGPT wrapper to cheat on interviews then sold the customer data to recruiters. The whole company promise is a scam, and useless since we have LLMs. HockeyStack held contests for people to win cars etc and never delivered. They also lied about having revenues and a product when they had nothing built. Along with Greptile they were doing 7day weeks of unp…

Wait what's the greptile story?
Post reply on HN